« List of all CVEs

CVE-2017-7555

Published: 8/17/2017 Last updated: 9/17/2024 Reserved: 4/5/2017

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

augeas

Products affected (1)

Product Vendor Version
augeas Red Hat, Inc. up to 21.0.0.Final

References (12)